NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 31 of 32
NCSC guidance

The NCSC’s clear, timely advice helps businesses of all sizes, charities, security professionals and members of the public, to understand and mitigate cyber threats.
From best practice frameworks to incident response support, the NCSC’s resources empower organisations to make informed decisions, build robust security strategies, and respond effectively to emerging risks.
This year, we set out clear timelines for migration to post-quantum cryptography, complemented by technical papers exploring advanced cryptographic methods and quantum networking technologies, laying the groundwork for long-term resilience. In support of the next generation of Active Cyber Defence (ACD) services, we published the results of the first ACD 2.0 experiment, focusing on external attack surface management.
On the human side of cyber security, we released a set of cyber security culture principles, new guidance on effective communication during incidents, and board-level training materials to strengthen cyber governance. We also provided practical advice on how to engage boards in meaningful cyber discussions.
Collaboration remained central to our approach. Working with international partners, including the Five Eyes alliance, we co-authored guidance on digital forensics and protective monitoring. We also contributed to the growing conversation around passwordless authentication, publishing three blog posts on passkeys, which was a key theme at CYBERUK 2025:
- Trust the tech: Using password managers and passkeys to help you stay secure online
- Passkeys: Not perfect, but getting better
- Passkeys and their promise: A simpler alternative to passwords
In total, we published or refreshed 64 guidance and blog products, including 35 blog posts and 29 formal guidance documents.
Key guidance highlights
Among the major guidance published or updated this year were:
• Cyber Assessment Framework (CAF) 4.0
• Security Principles for Protecting Sensitive Personal Information (SPI)
• Software Security Code of Practice
• Securing HTTP-based APIs
• Security Practices for Domain Registrars
• Principles for Secure Privileged Access Workstations (PAWs)
• Network Security Fundamentals
• Assessing Forgivable vs Unforgivable Vulnerabilities
• Countering Malvertising
• Multi-Factor Authentication for Corporate Online Services